Terminology Index
Glossary
2953 terms
B32
Baseline Analysis
Establishing what normal activity looks like in an environment so that deviations stand out as worth investigating. In detection and SIEM work, the baseline is the reference against which anomalies are measured.
Many detections depend on knowing normal, typical login times, common processes, usual network volumes, because attacks often appear as departures from it. Building and maintaining baselines lets analysts spot first-seen or rare events and tune detections so they alert on the genuinely unusual.
Introduced in: SIEM Query Fundamentals
Examples
- Learning a server's normal outbound traffic so a spike stands out.
- Baselining which processes commonly run so a new one is noticeable.
- Establishing typical login hours to flag off-hours access.
Related
Alert Designprerequisite_ofFirst-Seen Detectionprerequisite_ofAlert Triage Methodologyrelates_toDetection Coveragerelates_toLookup Tablesrelates_toBaseline Behaviorrelates_toCredential Dumping Indicatorsprerequisite_ofDNS-Based Detectionprerequisite_ofIdentity Anomaly Detectionprerequisite_ofNetwork Anomaly Detectionprerequisite_ofOutlier Detectionprerequisite_ofProcess Anomaly Detectionprerequisite_ofStatistical Detectionprerequisite_ofAlert Triage Methodologyrelates_toBaseline Behaviorrelates_toDetection Coveragerelates_toFrequency Analysisrelates_toLOLBin Hunting Methodologyrelates_toLong Tail Analysisrelates_toStatistical Analysis for Detectionrelates_toTime-Series Analysisrelates_toTime-Series Detectionrelates_to
